Challenge Category

Reverse Engineering CTF Challenges

Static/dynamic analysis & binary deobfuscation.

Round duration

12 hours

Format

Jeopardy-style CTF

Team size

1–3 members

Reverse engineering is the practice of taking a compiled artefact and recovering what it does. In a CTF context the artefact is usually a stripped Linux ELF binary or a Windows executable that hides a flag behind some logic: a comparison you have to satisfy, an encryption routine you have to break, or control flow that has been deliberately twisted so a decompiler renders it as gibberish.

The skill being tested is patience plus structure. Nobody reverses a 4 MB binary by reading it top to bottom. You probe it first — run it, see what it does, feed it inputs and watch what changes — then narrow to the function that matters and only then start reading carefully. Good reversers form a hypothesis, test it cheaply, and discard it just as fast.

You do not need to be an expert to score here. A working knowledge of x86-64 calling conventions, the C runtime library and common compiler idioms covers most of what a mid-difficulty challenge asks for.

What you’ll actually face

Challenge types modelled on the work real security teams do, weighted toward the mid and upper difficulty bands.

Flag checks

The classic form: a routine compares your input against a transformed value. You recover the transformation, invert it, and recover the flag.

Obfuscated control flow

Opaque predicates, flattened dispatch tables and switch tables inserted specifically to defeat decompilers, requiring manual reconstruction of the real logic.

Packed and encrypted payloads

Binaries whose meaningful code is unpacked at runtime, so static analysis shows a stub. You need to dump the process after the unpacking stage completes.

Anti-analysis

Timing checks, debugger detection and environment probes that must be identified and bypassed before the real logic will run.

Embedded data

Flags or keys embedded as byte arrays, decoded by a small routine buried somewhere in a large binary. The reverse part is locating the decoder.

Algorithm reimplementation

Custom hash, compression or cipher routines you must reimplement in another language to compute a comparison value or decrypt a blob.

Tools you’ll reach for

  • Ghidra
  • IDA Free
  • radare2 / rizin
  • GDB & pwndbg
  • strace / ltrace
  • x64dbg (Windows)
  • Frida
  • Python + capstone / pyelftools

How to prepare

None of this is required to enter — it is simply the shortest path to scoring points in this discipline.

  1. Complete a Ghidra course — the "Intro to Reverse Engineering" free course from the training.github.com Ghidra track is the right starting point.

  2. Learn enough x86-64 to read a decompiled function without flinching: calling convention, stack frame, and what `rbp`-relative reads mean.

  3. Always run the binary first. Even when it does nothing useful, `strings`, its dynamic dependencies and its runtime behaviour tell you what to decompile.

  4. Practise on crackmes.one from easy to medium. There is no substitute for the first twenty binaries.

  5. Learn the handful of Ghidra shortcuts that matter — rename, retype, force-integer — because manual naming is what makes a function readable.

Quick facts

Everything about Ghost Protocol CTF 2.0 at a glance.

Online qualifier
17 October 2026 · 12 hours · remote
Grand finale
24 October 2026 · 12 hours · on-ground
Format
Jeopardy-style CTF
Team size
1–3 members (solo entry allowed)
Registration fee
Free per team
Prize pool
Up to ₹51,000
Challenge categories
10 disciplines
Eligibility
Any student in an undergraduate or postgraduate programme, any stream
Venue
NIET Greater Noida
Organised by
Cyber Invaders · NIET Greater Noida

Ready to prove it on the scoreboard?

Reverse Engineering is one of 10 disciplines in Ghost Protocol CTF 2.0. Entry is free and teams of 1–3 are welcome.